DRAFT – HAVE AN ATTORNEY REVIEWThis is a plain-language starting draft, not legal advice and not yet approved for use. Text in [square brackets] is a placeholder or a decision still to be made. Do not publish or rely on it until a licensed attorney in your jurisdiction has reviewed and edited it.

Privacy Policy

DRAFT · Last updated: [date] · Effective: [date]

The short version. The app keeps your jobs on your device first. If you sign in and turn on sync, a copy goes to our database provider (Supabase) so your devices and your clients’ approval links work. We don’t sell your data and we don’t run advertising trackers. You can export everything, and you can ask us to delete your account.

1. Who we are

[Your company / legal entity name] (“we”) runs Amberchalk (the “Service”). This policy explains what information the Service handles, where it lives, who else touches it, and the choices you have. Contact us at [email protected].

2. What we handle, and where it lives

InformationWhere it is storedWhy
Your projects, logs, schedule, contacts, change orders, financial entries, plans and settingsOn your device (browser storage). If you sign in and sync, also in our database (Supabase).To run the app, work offline, and keep your devices in step.
Photos, plan files (PDF/images) and receipt photosOn your device. If you sync, also in private file storage (Supabase). Photos attached to an approval request are copied to a private area so your client can see them.Progress records, takeoff, expense records, client approvals.
Account details: email address, company name, team members you inviteOur database (Supabase).Sign-in, team access, support.
Subscription details: plan, status, billing interval, renewal dates, Stripe customer and subscription IDsOur database; card and billing details are held by Stripe, not us.To bill you and apply the right plan limits.
Email we send for you (sign-in codes, invitations, notices)Sent through Resend; the recipient’s email address and message content pass through them.To deliver the emails you ask the app to send.
Client approval responses: the decision, typed name, any question or comment, timestamp, and an audit trailOur database, linked back to your change order or decision.To give you a record of what your client approved.
Technical request data (such as IP address and browser type)Normal server logs at our hosting (Cloudflare) and database (Supabase) providers.Running and securing the Service.

3. Data stored on your device

4. Cloud sync, Supabase and your clients

5. Payments (Stripe)

Paid plans are billed through Stripe. You enter card details on Stripe’s pages; we don’t receive or store the full card number. We receive and keep your plan, subscription status, billing dates and Stripe IDs. Stripe’s own privacy policy covers what it does with your information.

6. Email (Resend)

We use Resend to send sign-in codes, team and guest invitations, and other emails the Service sends. Resend processes the recipient address, the message and delivery information. We don’t use your client’s email address for our own marketing. [Add: any marketing email policy and unsubscribe handling if you plan to send product news.]

7. Text messages

Where the app opens a text-message draft on your phone, the message is sent by your own device and carrier, not by us. [If you add automated SMS notices (a Pro feature), name the SMS provider here and describe what it receives.]

8. How we use information

9. Cookies, local storage and tracking

The app uses browser storage to work and to remember your sign-in and settings. We don’t currently use advertising cookies or third-party analytics trackers. [Confirm; if you add analytics, list the tool and what it collects here and add a consent mechanism where required.]

10. Who we share with

Only service providers that help us run the Service (currently Supabase, Stripe, Resend and Cloudflare), people you choose to share with (like your clients and team), professional advisers, and authorities when the law requires it. If we are involved in a merger or sale, information may transfer to the new owner under this policy. Providers may process data in the United States and other countries. [Attorney: add international transfer language if you serve customers outside the US.]

11. How long we keep it

12. Your choices: export and deletion

13. Security

We use reasonable measures to protect data in the cloud, including sign-in, encrypted connections, row-level access controls and private file storage. No system is perfectly secure. You are responsible for your device security, your sign-in email, and who you invite. If we learn of a breach that affects you, we will notify you as the law requires.

14. Children

The Service is for businesses and is not directed to children under 18. We don’t knowingly collect information from children.

15. Changes

We may update this policy. We will post the new version here and, for material changes, tell you through the app or by email before it applies to you.

16. Contact

[Your company / legal entity name]
[Postal address]
[email protected]